Jump to content

Apple has released their second biggest security update of the year, covering 25 vulnerabilities in 20 components.

 

Most of the vulnerabilities could allow an attacker to execute malicious code, although no exploits have been reported so far. Components at risk include iChat, fetchmail and Libinfo. Apple has also addressed an issue with the Login Window that would allow the local user to obtain system privileges and execute arbitrary code. You can learn more about the vulnerabilities here.

 

Early indications suggest that the update is safe to run on OSX86 installations.


User Feedback

Recommended Comments

cringemaster

Posted

Just started to downloading it...

 

At least this stuff gets caught before it becomes an issue.

Xenctuary

Posted

Updating my iMac now, thanks for the heads up!

errandwolfe

Posted

Installed with no problems (except an extra reboot after initial install) on my desktop. Specs are in my sig.

tomozj

Posted

Meh, I actually found a similar exploit with the login window... I won't mention more about it - I'll go report. Forgot about that one lol.

 

Thanks for the info on the update ;)

 

-tj

Takuro

Posted

Does anybody know that if it fixes login window vulnerabilities that it actually updates the binary file in loginwindow.app/contents/resources/macos/loginwindow? I have to use the Netkas patch for the 10.4.9 loginwindow, so I'm wondering if I'll have to reapply it.

tomozj

Posted

Well I found a bug that allowed me to run scripts under root in the loginwindow. I guess it fixes stuff in that area.

 

If you're using remote desktop, then patch it :thumbsup_anim:

 

-tj

mac.nub

Posted

Thanks! :) Updating my Hackintosh now :(

Edit: I can confirm that this worked fine on my Dell Inspiron 6400.

maculas

Posted

Just installed! Works great! 1 extra reboot and it was ready for use! No problems at all, just back up your 10.4.4 login fix!

Zulu.Walker

Posted

Security Update fixed some vulnerabilities that I was trying to track down for quite some time since I updated to 10.4.9. Now I have a cleaner console log output. Works great.


×
×
  • Create New...